⏐ Taklimat Pagi
Taklimat Pagi Saya
🔗 baca_penuh: pagi.hejes.my/2026/09/28
> ringkasan_ai
# 🤖 AI & Machine Learning
✅ **OpenAI: Stargate, "o" Assistant & Pro Max** [OpenAI/BleepingComputer] — OpenAI tengah scale-up infra Stargate untuk AGI, test assistant "o" yang sentiasa *on*, dan khabarnya nak launch plan Pro Max harga $500/bulan.💡 **Kenapa Penting** — OpenAI makin agresif nak dominate *enterprise* dan *high-end* users.
✅ **Claude Marketplace & Plugins** [BleepingComputer] — Anthropic tukar Claude jadi marketplace dengan lebih 2,000 plugins dan connectors.💡 **Kenapa Penting** — Claude sekarang bukan sekadar chatbot, tapi dah jadi ekosistem tool.
✅ **Gemma 3n & Nemotron Nano VLM** [HuggingFace] — Model open-source terbaru dari Google (Gemma 3n) dan NVIDIA (Nemotron Nano) dah masuk Hugging Face.💡 **Kenapa Penting** — Pilihan model *lightweight* untuk dev makin banyak.
✅ **Isu "Goblin" GPT-5** [OpenAI] — OpenAI explain kenapa GPT-5 ada quirk pelik (output goblin) dan macam mana dorang fix benda tu.💡 **Kenapa Penting** — Menarik nak tahu macam mana *personality* AI boleh "tergelincir".
✅ **Agent Memory & Decision Trees** [Hacker Noon] — Ada guide baru pasal cara bina memori AI agent supaya tak lupa info penting dan framework untuk PM decide tahap autonomi AI.💡 **Kenapa Penting** — Penting kalau Master nak optimize AI agent sendiri.
# 🛡️ Cybersecurity (Kritikal!)
✅ **Citrix NetScaler Zero-Day RCE** [CISA/BleepingComputer] — Ada 8 vulnerability baru, termasuk 2 Zero-Day yang tengah kena exploit sekarang untuk *Remote Code Execution*.💡 **Kenapa Penting** — Bahaya gila, kena patch segera kalau guna Citrix.
✅ **Obot Critical Vulnerabilities** [CVE Feed] — Siri CVE baru (101084, 101062, 101064, 101065) dedahkan isu *auth bypass* dan SSRF dalam platform Obot.💡 **Kenapa Penting** — Kalau Master guna Obot AI agent, tolong update version sekarang.
✅ **Cloudflare Container Flaw** [BleepingComputer/Hacker News] — Cloudflare dah fix bug yang bagi customer baca data "sampah" customer lain dalam container yang sama.💡 **Kenapa Penting** — Isu *cross-tenant data leak* ni sensitif untuk trust customer.
✅ **Microsoft SharePoint & Others Exploited** [SecurityWeek/Hacker News] — CISA masukkan flaw SharePoint, WSO2, dan Adobe Commerce dalam list KEV sebab memang tengah kena serang.💡 **Kenapa Penting** — Signal jelas yang attacker tengah target software enterprise besar.
✅ **Advanced Account Security OpenAI** [OpenAI] — OpenAI perkenalkan login tahan-phishing dan recovery lebih kuat.💡 **Kenapa Penting** — Account Master lebih selamat dari kena hijack.
# 💻 Tech & Dev
✅ **AI Coding Agents & IP Indemnity** [MarkTechPost] — Perbandingan kontrak Copilot, Cursor, Devin dll dari segi kos dan perlindungan undang-undang (IP).💡 **Kenapa Penting** — Penting untuk tahu siapa tanggung risiko kalau AI generate code yang langgar copyright.
✅ **Google Research MSEB** [MarkTechPost] — Tutorial coding untuk benchmark sound encoder terbaru dari Google.💡 **Kenapa Penting** — Berguna kalau Master nak explore AI audio/sound.
# 🇲🇾 Lokal & Lain-lain
✅ **Gadget Baru: Xiaomi 18 Pro & Samsung A08** [Amanz] — Xiaomi 18 Pro sah masuk Malaysia tahun ni, manakala Galaxy A08 (bateri 6000mAh) dah launch harga RM899.💡 **Kenapa Penting** — Update kalau Master nak upgrade phone atau cari phone bajet.
✅ **MyZakat 4.0 & Ubat Melalui Pos** [Amanz] — MyZakat upgrade interface baru, dan servis hantar ubat KKM jadi percuma bermula 1 Oktober.💡 **Kenapa Penting** — Info kebajikan yang memudahkan urusan harian.
✅ **Anthropic CEO & Donald Trump** [TechCrunch] — Dario Amodei (CEO Anthropic) bakal dinner one-on-one dengan Trump.💡 **Kenapa Penting** — Politik US akan beri kesan besar pada regulasi AI global.
🔥 Top Picks
**Citrix NetScaler Zero-Day** (Sebab ni *emergency* security)
**OpenAI "o" & Pro Max** (Sebab nak tengok sejauh mana OpenAI nak "peras" duit user)
**Claude Marketplace** (Sebab ni game-changer untuk productivity)
> ls -la berita/
📌 Lain-lain
3The SDP Offer/Answer Rules That Bite During WebRTC Renegotiation
Why WebRTC renegotiation breaks: a practical guide to SDP m-lines, transceiver ordering, rollback, implicit descriptions, and negotiation errors.
Anthropic’s CEO is about to have dinner with President Trump
This will be the first one-on-one meeting between Dario Amodei and Donald Trump
(LoRA) Fine-Tuning FLUX.1-dev on Consumer Hardware
🧠 AI/ML
24Can Muse overcome Meta’s trust issues?
On Equity, we discussed how Meta's AI announcement managed to steal the spotlight from OpenAI and Anthropic.
Building the compute infrastructure for the Intelligence Age
OpenAI scales Stargate to build the compute infrastructure powering AGI, adding new data center capacity to meet growing AI demand.
Insta360 Dilaporkan Sedang Bangunkan Kaca Mata Pintar Tersendiri
Insta360 sedia menempa nama pada arena global melalui penawaran kamera aksi 360-darjah. Menariknya, kini dengan pelbagai pihak menawarkan kaca mata pintar, hadir laporan mengatakan Insta360 turut sedang pertimbangkan untuk memperkenalkan kaca mata pi
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]
Training and Finetuning Sparse Embedding Models with Sentence Transformers
Where the goblins came from
How goblin outputs spread in AI models: timeline, root cause, and fixes behind personality-driven quirks in GPT-5 behavior.
How Much Should AI Be Allowed to Decide in Your Product? A PM's Decision Tree
"Can AI do this?" is the wrong question. A PM's decision tree for sorting AI features by what a wrong answer costs and who absorbs it.
Gemma 3n fully available in the open-source ecosystem!
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier containers h
Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secr
Anthropic’s Dario Amodei gets the SNL treatment
"AI is the devil and I its maker."
OpenAI and PwC collaborate to reimagine the office of the CFO
OpenAI and PwC are partnering to help enterprises use AI agents to automate finance workflows, improve forecasting, strengthen controls, and modernize the CFO function.
MyZakat 4.0 Diumumkan Dengan Antaramuka Serta Fungsi Lebih Mesra Pengguna
MyZakat 4.0 diperkenalkan sebagai platform zakat utama versi terbaharu di Malaysia. Ia hadir dengan pembaharuan mesra pengguna yang menjadikan pengalaman menunaikan zakat lebih mudah serta relevan dengan keperluan masyarakat moden. MyZakat 4.0 kini b
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]
Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...]
Sennheiser Momentum 5 review: Great sound, incredible battery life, and few compromises
I spent the last few weeks with the Sennheiser Momentum 5 to determine if this pair actually stands out, testing everything from sound quality and noise cancellation to comfort and battery life.
Transformers backend integration in SGLang
Penghantaran Ubat Melalui Pos Dikecualikan Bayaran Berkuat-kuasa 1 Oktober 2026
Kerajaan melalui Kementerian Kesihatan sedia menawarkan perkhidmatan Ubat Melalui Pos, membolehkan para pesakit untuk memohon agar ubat dihantar terus ke rumah, dan penghantaran yang dihantar melalui Pos Laju ditanggung oleh pesakit. Segala proses be
Siri Xiaomi 18 Pro Disahkan Memasuki Pasaran Malaysia Tahun Ini
Siri Xiaomi 18 Pro baru sahaja dilancarkan di China dan kini disahkan akan memasuki pasaran Malaysia pada tahun ini. Pengumuman tersebut dibuat melalui kemas kini di Facebook semalam dan ia menarik perhatian ramai khususnya peminat setia. Promosi ras
How OpenAI delivers low-latency voice AI at scale
How OpenAI rebuilt its WebRTC stack to power real-time Voice AI with low latency, global scale, and seamless conversational turn-taking.
OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]
Designing Agent Memory for Freshness, Supersession, and Retention
AI agents can retain outdated or sensitive information. The FRESH Memory Model offers a practical way to make agent memory safer and more reliable.
Why AI Agents Forget Everything (and How to Build Ones That Don't)
Learn how agent memory captures events, retrieves relevant context, and forgets outdated information to make AI interactions more useful and personal.
Welcome the NVIDIA Llama Nemotron Nano VLM to Hugging Face Hub
🛡️ Cybersecurity
18CVE-2026-101084 - obot before v0.21.1 Authorization Bypass via /mcp-connect
CVE ID :CVE-2026-101084 Published : Sept. 27, 2026, 9:17 p.m. | 2 hours, 28 minutes ago Description :obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restric
CVE-2026-96282 - Flatpak: flatpak: extension metadata path traversal file existence oracle
CVE ID :CVE-2026-96282 Published : Sept. 27, 2026, 10:17 p.m. | 1 hour, 9 minutes ago Description :A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listin
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777,
Introducing Advanced Account Security
Introducing Advanced Account Security: phishing-resistant login, stronger recovery, and enhanced protections to safeguard sensitive data and prevent account takeover.
CVE-2026-101062 - Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration
CVE ID :CVE-2026-101062 Published : Sept. 27, 2026, 9:17 p.m. | 2 hours, 28 minutes ago Description :Obot before v0.23.0 (affected versions Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and m
CVE-2026-101064 - Obot before v0.23.0 Server-Side Request Forgery via MCP
CVE ID :CVE-2026-101064 Published : Sept. 27, 2026, 9:17 p.m. | 2 hours, 28 minutes ago Description :Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify ar
CVE-2026-100886 - Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication
CVE ID :CVE-2026-100886 Published : Sept. 27, 2026, 11 p.m. | 26 minutes ago Description :A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelli
CVE-2026-100885 - Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization
CVE ID :CVE-2026-100885 Published : Sept. 27, 2026, 10:45 p.m. | 41 minutes ago Description :A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanIn
CVE-2026-100884 - Krayin laravel-crm attachment-download Endpoint acl.php resource injection
CVE ID :CVE-2026-100884 Published : Sept. 27, 2026, 10:30 p.m. | 56 minutes ago Description :A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/sr
CVE-2026-101065 - Obot Quickstart Docker Deployment Unauthenticated Admin Access
CVE ID :CVE-2026-101065 Published : Sept. 27, 2026, 9:17 p.m. | 2 hours, 28 minutes ago Description :Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the REA
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affe
CVE-2026-96283 - Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull
CVE ID :CVE-2026-96283 Published : Sept. 27, 2026, 10:17 p.m. | 1 hour, 9 minutes ago Description :By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal trackin
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28. The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek.
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitat
How the CISO CFO Relationship is a Key to Cybersecurity Success
Building a financial bridge: Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk and enable business growth are better prepared to face today's threat landscape.
CVE-2026-101090 - Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri
CVE ID :CVE-2026-101090 Published : Sept. 27, 2026, 9:17 p.m. | 2 hours, 28 minutes ago Description :Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/
Citrix confirms two NetScaler RCE zero-days exploited in attacks
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. [...]
⚡ Tech/Dev
3A Coding Guide to Google Research’s MSEB: Writing Sound Encoders to the Benchmark Contract and Scoring Them Across Classification, Clustering, Retrieval and Segmentation
A comprehensive coding tutorial on Google Research's Massive Sound Embedding Benchmark (MSEB), demonstrating how to implement custom sound encoders, drive classification, clustering, retrieval, and segmentation evaluators, and analyze multi-task benc
AI Coding Agents for Enterprise: IP Indemnity, Data Residency and 500-Seat Cost Compared
We read the contracts behind GitHub Copilot, AWS Kiro, Cursor, Devin and Windsurf. Copilot and Kiro offer uncapped indemnity on generated code. Cognition's standard terms exclude outputs entirely. Here is how 500 seats compare on legal exposure, prom
TechCrunch Mobility: AV companies pick their lanes
Welcome back to TechCrunch Mobility, your hub for the future of transportation and now, more than ever, the role AI is playing in it.
🇲🇾 Malaysia/Lokal
2Bittensor’s Real Experiment Is Paying Markets to Produce Intelligence
Bittensor is easier to understand as a market for measurable digital work. Here’s how subnets, validator scoring, alpha tokens, and TAO incentives fit together.
Samsung Galaxy A08 Berharga RM899 Di Malaysia – Hadir Dengan Bateri 6000mAh
Samsung Malaysia kini mengumumkan penawaran telefon pintar Galaxy A08 secara rasmi untuk pasaran Malaysia, dimana ia ditawarkan pada harga RM899. Telefon ini memfokuskan kepada penggunaan janga masa lama melalui bateri 6000mAh yang disertakan bersama